Version: 1.1.1
Last Updated: September 2026
Published by: Light Bulb Ideas LLC
App: https://security.lbiwatchdog.com
LBI Security is the customer-facing app for alarm panels connected through a LBI WatchDog. It is separate from lighting control.
| Who | Where to sign in |
|---|---|
| Home / site users (arm, disarm, zones) | https://security.lbiwatchdog.com |
| Integrators (wire the panel, name zones, notify rules) | https://lbiwatchdog.com → device → Settings → Security System |
| Super Admins | Both apps; SA Diagnostics still shows agent health |
WatchDog does not replace the panel keypad, monitoring station, or ElkRP / DLS programming software. It reads zone and arm state from the panel and sends arm/disarm/bypass commands using a user code entered at command time. Codes are not stored in the cloud unless the person checks Remember my code on this device (stored only in that browser).
If Security is not enabled on a WatchDog, the app shows: Security is not active on this system. Contact your system integrator or dealer to enable it.
| Vendor | Connection options | WatchDog modules |
|---|---|---|
| ELK M1 Gold | RS-232 Port 0 (USB–RS232) or Ethernet via M1XEP (TCP 2101 / SSL 2601) | elk_bridge.py |
| DSC PowerSeries Pro | TL280 ITv2 over IP (ports 3072 / 3073) or TL280LE(R) RS-232 | dsc_bridge.py |
Agent 6.34.0+ required for the Security Bridge. 6.37.7+ for Prepare WatchDog (install libraries and scan USB serial from Settings — no SSH).
Field wiring for ELK is in the ELK Install Manual (including cellular-only / EXVIST LTE). 12 V / RV extras: ELK_M1_WATCHDOG_INSTALL.md. This Security manual covers day-to-day app use plus Settings configuration.
Security Only and Security Admin accounts cannot sign in to the lighting dashboard. Lighting users (company admin, manager, standard user) can use the Security app when the site has a bridge enabled.
Add to the phone home screen from the browser (PWA) for one-tap access.
The System page shows arm state with a color emblem:
| State | Meaning |
|---|---|
| Disarmed | Panel is off |
| Away | Armed away (or vacation) |
| Stay | Armed stay / night |
| Armed | Armed (other armed mode) |
| Offline | Bridge disabled, WatchDog offline, or panel not connected |
| Unknown | Bridge has not reported a state yet |
Buttons (shown only if your account is allowed):
Enter your panel user code (4 or 6 digits as programmed on the panel) before tapping a button. Check Remember my code on this device only on a private phone.
The code is sent to WatchDog and then to the panel. Invalid or restricted codes fail at the panel; the app shows the bridge error.
Refresh reloads the selected site. The bridge banner reports connected / listening / last error.
If your account is view-only: Your account can view status only. Contact your administrator for arm/disarm access.
Open Zones in the sidebar. Each row shows:
Bypass changes are sent to the panel immediately. Integrators also set per-zone bypass and auto-bypass in WatchDog Settings; those rules apply when arming with open zones.
Zone names are configured in WatchDog Settings → Security System, not in the Security app.
Email and SMS alerts for a zone can include one-tap snooze links: 30 minutes, 24 hours, or 1 week. After tapping a link, a confirmation page is shown.
To turn notifications back on before the timer ends:
Snooze only pauses WatchDog notifications for that zone. It does not disarm the panel or bypass the zone.
| Role | Lighting dashboard | Security app |
|---|---|---|
| Super Admin / Company Admin | Full | Full (including Users) |
| Manager / Standard User | Per tab permissions | Full panel access unless a Security profile is set on the user |
| Security Only | Blocked | Arm/disarm (no bypass by default); email alerts |
| Security Admin | Blocked | Arm/disarm/bypass; manage Security users; email + SMS |
Set in the Security app Users tab (Security Admin / company admin / super admin):
| Profile | Arm | Disarm | Bypass |
|---|---|---|---|
| Arm / Disarm / Bypass | Yes | Yes | Yes |
| Arm / Bypass | Yes | No | Yes |
| Disarm | No | Yes | No |
You can add the user in either app:
Security app: Users → + Add
User
WatchDog: Users → Add User, role
Security Only or Security Admin
+15551234567).These users sign in at security.lbiwatchdog.com only. Lighting Notifications tab does not set Security recipients.
On the same Users page, Panel Users lists keypad codes on the ELK or DSC panel. Add/edit/remove requires a master / current code at save time. Codes are sent to the panel and are never stored in the cloud. User 1 can be edited but not deleted.
On lbiwatchdog.com (or beta) → select WatchDog → Settings → Security System:
elkm1-lib / pyserial, adds the agent user to
dialout, and scans USB serial ports. No SSH required.Bridge status should move to Connected (ELK) or Listening — awaiting TL280 then Connected (DSC IP). History records a config-change event.
Notify modes:
| Mode | When alerts send |
|---|---|
| Always | Even if disarmed |
| Armed only | Only while the partition is armed |
| Never | No WatchDog email/SMS for that zone |
Test connection (ELK) exercises the serial or M1XEP path from Settings.
Mobile control URL shown on the card: https://security.lbiwatchdog.com
M1 Gold Port 0 (female DB-9, DCE)
│ straight-through RS-232
▼
USB–RS232 adapter (FTDI, true RS-232 levels — not 3.3 V TTL)
│ USB
▼
LBI WatchDog
| Setting | Default |
|---|---|
| Serial device | /dev/ttyUSB0 (from Prepare WatchDog scan) |
| Baud | 115200 (must match Globals G34) |
| Format | 8N1 |
| Partition | 1 |
Do not share Port 0 with an M1XEP / C1M1. Unplug the Ethernet expander when using USB serial.
Program on the M1 (ElkRP Globals G29–42 or keypad): G34 = 9 (115200); G35–G40 Transmit… ASCII = YES. G35 and G36 are the minimum for arm/zone status.
Users and zones are programmed on the panel (ElkRP or keypad). WatchDog names are labels for the app and notifications.
ElkRP Network mode can use the same XEP when the WatchDog bridge is disconnected.
Firmware 4.5.14 / 5.1.14 or newer is required if you feed DC into the AC terminals (RV / off-grid). See the ELK install guide.
WatchDog listens; the TL280 connects inbound.
| WatchDog field | Typical value | TL280 section |
|---|---|---|
| Listen host | 0.0.0.0 |
— |
| Notification port | 3072 | [429] |
| Polling port | 3073 | [430] |
| Integration access code | as programmed | [423] |
| Partition | 1 | — |
On the TL280: enable Ethernet integration [425]; set Integration Server IP [428] to the WatchDog’s LAN address.
Status Listening — awaiting TL280 is normal until the communicator connects.
Max cable 8 ft. Adapter TX→panel RX, RX→TX, GND→GND.
Enable serial integration in [425]. Default baud
115200 [420]. Use Prepare
WatchDog to find /dev/ttyUSB0.
Security email/SMS are separate from lighting circuit alerts on the WatchDog Notifications tab.
https://security.lbiwatchdog.com/?device=…). Sign-in may
be requiredHistory on the lighting dashboard still records security config changes and many panel events for integrators.
When the site uses cellular for WatchDog, the standard modem is the EXVIST 4G LTE Dongle with EC25-AF Mini PCIe modem and SIM slot (Verizon / AT&T / T-Mobile / Rogers / U.S. Cellular / Telus).
LTE is cloud WAN only. The panel still talks to the WatchDog over RS-232 or Ethernet. Cell does not replace the keypad, monitoring-station radio, or ITv2/ASCII on the LAN.
Install with a security system:
connectivity.apn change (Admin Manual §6.13).ElkRP / DLS tunnels ride LTE when that is the WAN. ITv2 / ASCII never go over the radio to the panel vendor — only WatchDog cloud and the programming tunnel do.
| Symptom | What to try |
|---|---|
| “Security is not active” | Integrator: enable Security Bridge and Save in WatchDog Settings |
| “No active security systems” | User not assigned to the device; wrong company; bridge off |
| Offline / unknown arm state | WatchDog online? USB seated? M1XEP IP pingable? DSC TL280 [428] pointing at WatchDog? |
| Prepare WatchDog timeout | Agent 6.37.7+; device online; wait for command to complete |
| No serial ports listed | Plug in FTDI adapter; click Prepare WatchDog again |
| ELK connected but no zones | G35/G36 ASCII transmit; baud matches G34; correct partition |
| DSC stays Listening | TL280 Ethernet integration; server IP = WatchDog; ports 3072/3073; access code [423] |
| Arm/disarm fails | Valid panel user code for that partition; permission profile allows the action |
| No email/SMS | Notify mode not Never; user Alerts via; snooze not active; SMS consent; E.164 phone |
| Cannot see Users tab | Need Security Admin, company admin, or super admin |
| LTE up but panel Offline | LTE is WAN only. Check USB serial vs EXVIST dongle (two different USB devices). Cellular-only: USB Ethernet + Panel on WatchDog Ethernet |
| Modem present — not connected | SIM seated; wait 60s; wrong APN (Super Admin); role not Disabled |
Do not use WatchDog GPIO UART pins or USB-TTL 3.3 V dongles for ELK Port 0.
Light Bulb Ideas LLC
Phone: 617-618-LBI1
Email: info@lbiwatchdog.com
Security app: https://security.lbiwatchdog.com
WatchDog: https://lbiwatchdog.com
Integrator wiring: ELK Install Manual / DSC
Install Manual. 12 V / RV:
docs/ELK_M1_WATCHDOG_INSTALL.md
| Version | Date | Changes |
|---|---|---|
| 1.1.1 | September 2026 | Public copy: call the on-site controller LBI WatchDog, not Pi. |
| 1.1.0 | September 2026 | Users: WatchDog + Security app fields (Alerts via, consent, profiles). Notifications: lighting vs Security, Respond, browser push. EXVIST 4G LTE for WatchDog WAN on security jobs. |
| 1.0.0 | August 2026 | Initial Security manual: app use, roles, snooze, ELK RS-232/M1XEP, DSC ITv2/RS-232, Settings Prepare WatchDog |
© 2026 Light Bulb Ideas LLC. All rights reserved.
This manual is proprietary and confidential. Unauthorized distribution is prohibited.